HIPAA Violations Are Still Mostly People, Not Technology: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I learned a long time ago, when I served in that contradiction of terms, military intelligence, that the big risk, at that time to defense .. read more
HIPAA & CORONAVIRUS BLOG POST 4―Enforcement Discretion for Telehealth Remote Communications during the COVID-19 Nationwide Public Health Emergency: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Roger Severino, the Director of the Office for Civil Rights (“OCR”) of the U.S. Department of Health and Human Services (“HHS”) has announced that OCR .. read more
HIPAA and Coronavirus 2—HHS Limited Waiver: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As a followup to my March 2, 2020, blog post, HIPAA and Coronavirus (and certainly not in reaction to it), the U.S. Department of Health .. read more
HIPAA and Coronavirus: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In case you missed it, the Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) recently issued a bulletin titled HIPAA Privacy .. read more
HHS Office for Civil Rights and the Department of Education Issue Updated Guidance on Sharing Student Health Records under HIPAA and FERPA: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Having had the good fortune to be a HIPAA consultant for several universities, I am quite aware of the confusion that could result from possibly .. read more
Are You Encrypting Your Laptops and Other Portable Devices? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although encrypting portable devices is not absolutely required by the Security Rule—that is, it is an addressable, not a required, implementation specification—another seven-figure penalty demonstrates .. read more
OCR Reveals Its Right of Access Enforcement Priorities: HIPAA & HITECH Act Blog by Jonathan P. Tomes
At a major annual HIPAA conference, Roger Severino, Director of the Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”), revealed its .. read more
Deny Me My Records? Pay $85,000 under the HIPAA Right of Access! HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have previously written about one of the easiest ways to get a civil money penalty (or a state sanction (see California)—that is, failing to .. read more
Changed HIPAA and HITECH Penalties—a Boon or a Trap for the Unwary: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Department of Health and Human Services (“HHS”) has announced a new penalty structure for the civil money penalties (“CMPs”) for HIPAA violations that apparently .. read more
Business Associates Face the Same HIPAA Penalties as Covered Entities: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Attorney General of New Jersey recently announced a $200,000 settlement for a HIPAA violation with a business associate, one of the classic examples of .. read more